Appearance
Why It Matters
Webhook collectors make exfiltration easy because they can receive arbitrary posted payloads with minimal authentication or setup.
What Triggers
SEC679 matches committed Claude command hooks that combine secret markers with webhook endpoints such as Slack or Discord webhook URLs.
False Positives
Benign webhook notifications should not contain copied secret values. This rule only targets the secret-bearing variant.
Remediation
Remove the secret-bearing webhook post from the committed Claude hook and keep notifications free of credential material.